Companies are adopting AI tools faster than they are testing whether their underlying data is appropriately secure, a new report from governance firm Syskit suggests.
Based on a survey of 327 IT and security decision-makers at U.S. and U.K. organizations with at least 500 workers, Syskit's State of Microsoft 365 Governance Report, published Sept. 10, found that 76% of the companies surveyed had deployed or tested enterprise AI tools such as Copilot in their Microsoft 365 environments, but less than half (43%) had conducted a thorough review of file permissions and potential oversharing risks prior to deployment, and the rest skipped the review process or reviewed only partially.
There was a similar gap for oversight over AI agents. While 91% of respondents said they were confident about their knowledge of what AI agents were and had access to, in practice, barely one in five companies (22%) had a formal policy outlining permitted agents' access, and roughly one in 10 (9%) had an agent that had inherited all the permissions of the person who had deployed it.
"If you look at tools such as Copilot, you can see the value it can bring," said Syskit CEO Toni Frankola, noting that some content could be exposed purely based on permissions that had been set years ago and then simply forgotten about, and that AI had removed the friction that had previously prevented accidental exposure.
"Permission audits may be the most critical and least desirable step in preparing a safe and secure AI deployment."
The report also highlighted areas of weakness in Microsoft 365 environments overall. Roughly 41% of organizations had SharePoint sites that were publicly available with no access restrictions, 35% had visible files for past employees, and a third had files shared publicly with "Everyone." Ownerless content was the biggest concern, with 47% of organizations citing orphaned teams, groups and sites, which had no one accountable for reviewing or securing them, despite being accessible to an AI just as readily as any other content.
"There seems to be a disconnect between confidence and reality with regard to the management and control of data and information," said Frankola. "While eight in 10 (83%) organizations feel confident that they know exactly who can access specific sensitive information, only 4% could provide a complete access report for an auditor within an hour if asked … and more than half would need at least a day to prepare one."
Perhaps most concerningly, 90% of organizations said they had suffered or suspected a security incident related to incorrectly configured permissions or excessive access in the last two years, and 39% confirmed that a security incident had definitely occurred.
Read the original article: